PRIVACY POLICY
LensCAD — PartCraft LLC
Version: 10
Effective Date: September 4, 2026
Last Updated: August 30, 2026
Privacy Contact: [email protected]
1. INTRODUCTION
PartCraft LLC ("PartCraft", "we", "us") operates LensCAD, a web application that converts a photograph of a physical part into a dimensionally-scaled DXF drawing. This Privacy Policy explains what we collect, why, who else touches it, and how long we keep it.
It applies to the LensCAD web application and the lens-cad.com website. It does not apply to anything you do with a DXF after you download it.
The short version
We collect the minimum needed to run an account, process your photographs into drawings, and take payment. We do not train AI models on your photographs, your drawings, or how you use the app. We do not sell, rent, or license your data to anyone. We run no advertising and no third-party analytics or tracking. Your photographs live on our servers only as long as it takes to work on them.
2. INFORMATION WE COLLECT
2.1 Account information
To create an account we collect your email address, a hashed password (we never store the password itself), your confirmation that you meet the minimum age, the version of our legal documents you accepted and when, and your plan status. We do not ask for your name, address, phone number, employer, or date of birth.
2.2 Payment information
Payments are processed by Stripe (Stripe, Inc., stripe.com). Checkout, and the billing portal where you can see your invoices and cancel a plan, take place on Stripe's pages under Stripe's own privacy policy. PartCraft never receives or stores your full card number, CVC, or bank credentials — those go directly to Stripe. We receive and store only a customer reference, the plan or item purchased, the amount, the date, and the last four digits and brand of the card for your receipts and support. Billing address and tax location may be collected by the processor where law requires it.
2.3 Photographs and drawings you submit
When you upload a photograph, the following happens before it is written to disk:
- Metadata is stripped. The image is re-encoded without EXIF, which removes GPS coordinates, capture timestamps, and camera serial numbers. A limited, sanitized set of camera facts — make, model, focal length, lens model — is read first and kept, because lens correction needs it. No GPS, no timestamps, no serial numbers are kept.
- Faces are blurred. An automated detector locates faces and blurs them irreversibly. This is best-effort — it can miss a face or flag something that is not one — and it exists to reduce incidental capture of people in the background of a workshop photo. No facial geometry or biometric identifier is extracted or retained; detection locates a region to blur and nothing else.
We also hold, for the working life of a job: the corrected image, the geometry you trace, dimensions and scale calibration, and the DXF we generate for you.
2.4 Technical and diagnostic information
Our servers keep ordinary operational logs — IP address, request time, endpoint, error traces. These are used to keep the service running and to investigate faults.
If you choose to send us a diagnostic bundle for a trace that went wrong, it contains the job's images and settings. That is an affirmative act you take, one job at a time; nothing is sent automatically.
Smart Trace run records and credit history. For each Smart Trace run we keep, tied to your account, the time, the model setting, whether it succeeded, how long it took, the token counts and cost of the AI request, and the credits charged. We also keep a ledger of every credit added to or removed from your account and the reason. These exist so that you can see exactly what you were charged and why, and so that we can run and price the service. They contain no photographs and no geometry.
2.5 What we do not collect
We do not collect precise location, contacts, biometric identifiers, browsing activity on other sites, or advertising identifiers. We set no advertising cookies and embed no third-party analytics, tag managers, or social pixels. The cookies we set are the session cookie that keeps you logged in and your saved preferences.
3. HOW WE USE INFORMATION
3.1 To run the Services
We use your information to authenticate you, process your photographs into drawings, meter the features your plan includes, take payment, send you service email you need (password resets, receipts, material changes to these terms), and answer your support requests.
3.2 To keep the Services working
We use aggregate and de-identified information to find and fix bugs, measure performance, and decide what to build. We do not profile individual users, and we do not use anything we hold about you to make decisions about your pricing, feature access, or marketing segmentation.
3.3 What we do NOT use your information for
To be unambiguous:
- We do not train AI or machine-learning models on your photographs, your drawings, your geometry, or your interaction history — not generative models, not computer-vision models, not our own and not anyone else's.
- We do not build or sell training datasets and no longer license data to third parties for any purpose.
- We do not sell or rent your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law.
4. WHO ELSE PROCESSES YOUR INFORMATION
4.1 Service providers
We use a small number of providers to run LensCAD. Each acts on our instructions under contract, for the stated purpose only:
- Hosting and database — runs the application and stores account data.
- AI trace processing (Smart Trace only) — when you run Smart Trace, the photograph for that job is sent to our AI provider to be analysed, and the traced outline is returned. This happens only on the runs you start; ordinary edge detection, perspective correction, scale calibration, manual tracing, and DXF export all run on our own servers and send your photograph nowhere. Our provider processes the image to answer that one request under a business agreement that does not permit training on it. If you would rather no image ever leave our servers, do not use Smart Trace — every other part of LensCAD works without it.
- Payment processing (Stripe) — takes payment, holds card data, and hosts the billing portal, as described in Section 2.2.
- Transactional email — delivers password-reset and account email.
- DNS and network protection — routes and protects traffic to the site.
An IP-based country lookup runs only if regional availability limits are switched on. It is currently off, and when off, no IP address is sent to that service.
4.2 Legal and business transfers
We may disclose information if required by law, valid legal process, or to protect the rights and safety of our users or the public. In a merger, acquisition, or sale of the business, information may transfer to the acquiring entity subject to equivalent protections and the same purpose limits stated here; we will give notice at least 30 days in advance.
5. RETENTION
- Photographs, corrected images, geometry, and generated DXF files are held in per-job working storage while you work. This storage is ephemeral — it is cleared whenever the application is redeployed or its container is recycled, which happens routinely, and in any case is deleted within thirty (30) days. We do not archive your photographs, and we keep no copy after that.
- Saved projects (
.lcadfiles) are downloaded to your own device. We do not retain a copy. - Account records are kept while your account is open and for up to 30 days after you delete it, after which they are removed from active systems.
- Payment and tax records are kept as long as tax and accounting law requires, typically seven years.
- Operational logs are kept for up to 90 days.
- Diagnostic bundles you send us are deleted once the issue is closed, and within 12 months regardless.
6. SECURITY
We encrypt data in transit with TLS. Passwords are stored only as salted hashes and are never recoverable. Stored account data and files are encrypted at rest by our infrastructure providers. Access to production systems is limited to personnel who need it. Uploads are stripped of metadata and face-blurred before they are written to disk.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal information, we will notify you and the authorities as applicable law requires.
7. CHILDREN
LensCAD is not directed to children. You must be at least 18 to hold an account, and we ask you to confirm that at sign-up. We do not knowingly collect personal information from children under 13. If you believe a child has given us information, contact us at [email protected] and we will delete it.
8. INTERNATIONAL USERS
LensCAD is operated from the United States and your information is processed there. If you use the Services from outside the United States, you are transferring your information to the United States, where privacy law differs from your own.
9. YOUR RIGHTS AND CHOICES
9.1 Rights available to everyone
Whatever jurisdiction you are in, you may ask us to access a copy of what we hold about you, correct anything inaccurate, delete your account and its data, or export your data in a portable form. Email [email protected]. We will respond within the time applicable law requires and will not charge you or degrade your service for asking.
9.2 California residents
Under the CCPA as amended by the CPRA you additionally have the right to know the categories and specific pieces of personal information collected, the sources, the business purpose, and the categories of third parties it is disclosed to; to delete; to correct; to limit use of sensitive personal information; and not to be discriminated against for exercising any of these rights.
We do not sell personal information and we do not share it for cross-context behavioural advertising, so no opt-out of sale or sharing is required — there is nothing to opt out of. We honour Global Privacy Control signals. We do not use or disclose sensitive personal information beyond the purposes permitted without a right to limit.
9.3 EEA and UK residents
Where the GDPR or UK GDPR applies, our legal bases are: performance of a contract for account, processing and payment data; legitimate interests for security, fault diagnosis, and service improvement; and consent where we ask for it. You have the rights of access, rectification, erasure, restriction, portability, and objection, and you may complain to your supervisory authority.
10. CHANGES TO THIS POLICY
We may update this Policy. For a material change that broadens how we use information you have already given us, we will give notice and obtain your affirmative agreement before it applies to you. For lesser changes we will post the revised Policy with a new Last Updated date. We will not retroactively apply a broader use to information collected under an earlier version.
11. CONTACT
PartCraft LLC
5101 Caves Hwy
Cave Junction, Oregon 97523
United States
Privacy: [email protected]